TIP: You can type at any time to perform a new search.
Customer Portal
portal · odoo/odoo
Security findings
- Repository
- odoo/odoo · module folder
- Module version
- 0.1.0
- Category
- Hidden
- Folder size
- 2.64 MB
- License
- LGPL-3
- Application
- No
- Auto-installable
- No
- Website
- None
- Last tracking update
- 2026-10-05 06:12:50
- Authors
- Odoo S.A.
- Maintainers
- Odoo S.A.
- Committers
- Xavier Morel, Xavier ALT, Raphael Collet, Thibault Delavallée, odoo, Odoo Translation Bot, Christophe Matthieu, Aaron Bohy, Géry Debongnie, qsm-odoo, Julien Castiaux, Xavier-Do, Victor Feyens, Adrien Dieudonné, Sébastien Theys, Julien Mougenot, std-odoo, Tiffany Chang (tic), Gorash, Romain Estievenart, Miquel Raïch, Nicolas Bayet, Alexandre D. Díaz, tsm-odoo, Mylyna Hy, amdi-odoo, Pierre-Yves Dufays, Robin Lejeune (role), Dylan Kiss (dyki), Antoine Boonen, FrancoisGe, Chong Wang (cwg), Xavier Bol (xbo), Brieuc-brd, divy-odoo, Zelong Lin, Maryam Kia, Louis (loti), kcv-odoo, Alex Kühn, Chrysanthe (chgo), mano-odoo, Harsh Shah, thle-odoo, Xavier Luyckx (xlu), prep-odoo, Rahil Ghanchi, Sébastien (blse), sben-odoo, Lucas Lefèvre (lul), Pierre Pulinckx, Michaël Mattiello, Sherif Gabr, anko-odoo, Krzysztof Magusiak (krma), Elier Ayala Bernal, pajo, defl, Giorgio Tocco (gito), akha, Julien Launois (jula), adip-odoo, Augustin (duau), Serhii Rubanskyi, Yagnik ✗ (yagp), h4818, Lionel Piraux (lipi), Benoit Socias (bso), Maxime de Neuville (mane), mibav-odoo, abbhi-Odoo, Ravij Parikh, orma-odoo, Mazen, assk-odoo, Atovange, Julien (jdeh), Farah (ahmfa), ELCO, Haja Ram, khaj-odoo, stefanorigano (sri), Krishna Patel, mear-odoo, qucol-odoo, Julien Coppin (jucop), djhan, Mark Orban (maorb), Julien Piron, Jean Schoenlaub, mekot-odoo
- Odoo dependencies
- Python dependencies
- None
- System dependencies
- None
- Required by
- account, auth_passkey_portal, auth_password_policy_portal, auth_totp_portal, digest, event, loyalty, mail_group, mass_mailing_sms, payment, portal_discuss, portal_rating, spreadsheet, test_mail_full, website, website_crm_partner_assign, website_payment
- Description
This module adds required base code for a fully integrated customer portal. It contains the base controller class and base templates. Business addons will add their specific templates and controllers to extend the customer portal. This module contains most code coming from odoo v10 website_portal. Purpose of this module is to allow the display of a customer portal without having a dependency towards website editing and customization capabilities.
Code Analysis
Views touched (40)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
footer_language_selector |
Footer Language Selector | ir.ui.view | qweb | Inherits portal.frontend_layout |
frontend_layout |
Main Frontend Layout | ir.ui.view | qweb | Inherits web.frontend_layout |
language_selector |
Language Selector | ir.ui.view | qweb | New |
message_document_unfollowed |
message_document_unfollowed | ir.ui.view | qweb | Inherits mail.message_document_unfollowed |
message_thread |
message_thread | ir.ui.view | qweb | New |
my_account_link |
Link to frontend portal | ir.ui.view | qweb | Inherits portal.user_dropdown |
pager |
Pager | ir.ui.view | qweb | New |
placeholder_user_sign_in |
User Sign In Placeholder | ir.ui.view | qweb | New |
portal.address_card |
Address Card | ir.ui.view | qweb | New |
portal.address_footer |
portal.address_footer | ir.ui.view | qweb | New |
portal.address_form_fields |
Address Details | ir.ui.view | qweb | New |
portal.address_list |
portal.address_list | ir.ui.view | qweb | New |
portal.address_management |
Address Management | ir.ui.view | qweb | New |
portal.address_warning_icon |
portal.address_warning_icon | ir.ui.view | qweb | New |
portal.my_addresses |
portal.my_addresses | ir.ui.view | qweb | New |
portal.portal_my_details |
Account Details | ir.ui.view | qweb | New |
portal.profile_picture_card |
Profile picture card | ir.ui.view | qweb | New |
portal.signature_form |
Ask Signature | ir.ui.view | qweb | New |
portal.user_sign_in_redirect |
User Sign In redirect | ir.ui.view | qweb | Inherits portal.user_sign_in |
portal_back_in_edit_mode |
Back to edit mode | ir.ui.view | qweb | New |
portal_breadcrumbs |
Portal Breadcrumbs | ir.ui.view | qweb | New |
portal_contact |
Contact | ir.ui.view | qweb | New |
portal_docs_entry |
My Portal Docs Entry | ir.ui.view | qweb | New |
portal_docs_entry_layout |
Use Pictograms | ir.ui.view | qweb | Inherits portal.portal_docs_entry |
portal_layout |
Portal Layout | ir.ui.view | qweb | New |
portal_my_contact |
portal_my_contact | ir.ui.view | qweb | New |
portal_my_home |
My Portal | ir.ui.view | qweb | New |
portal_my_security |
portal_my_security | ir.ui.view | qweb | New |
portal_record_sidebar |
My Portal Record Sidebar | ir.ui.view | qweb | New |
portal_searchbar |
Portal Search Bar | ir.ui.view | qweb | New |
portal_share_template |
portal_share_template | ir.ui.view | qweb | New |
portal_share_wizard |
portal.share.wizard | portal.share | form | New |
portal_sidebar |
Sidebar | ir.ui.view | qweb | New |
portal_table |
My Portal Table | ir.ui.view | qweb | New |
record_pager |
Portal Record Pager | ir.ui.view | qweb | New |
res_config_settings_view_form |
res.config.settings.view.form.inherit.portal | res.config.settings | form | Inherits base_setup.res_config_settings_view_form |
side_content |
side_content | ir.ui.view | qweb | New |
user_dropdown |
Portal User Dropdown | ir.ui.view | qweb | New |
user_sign_in |
User Sign In | ir.ui.view | qweb | Inherits portal.placeholder_user_sign_in |
wizard_view |
Grant portal access | portal.wizard | form | New |
HTTP endpoints (16)
| Route(s) | Handler | Auth | Type | Methods | Flags |
|---|---|---|---|---|---|
/my/account |
CustomerPortal.account |
user | http | ALL | website |
/my/address/archive |
CustomerPortal.address_archive |
user | jsonrpc | POST | sudo website |
/portal/attachment/remove |
CustomerPortal.attachment_remove |
public | jsonrpc | ALL | |
/my/counters |
CustomerPortal.counters |
user | jsonrpc | ALL | sudo website |
/my/deactivate_account |
CustomerPortal.deactivate_account |
user | http | POST | sudo website |
/my, /my/home |
CustomerPortal.home |
user | http | ALL | website |
/my/addresses |
CustomerPortal.my_addresses |
user | http | ALL | website |
/my/address |
CustomerPortal.portal_address |
user | http | GET | sudo website |
/my/address/country_info/<model("res.country"):country> |
CustomerPortal.portal_address_country_info |
public | jsonrpc | POST | sudo website |
/my/address/state_info/ |
CustomerPortal.portal_address_state_info |
public | jsonrpc | POST | sudo website |
/my/address/submit |
CustomerPortal.portal_address_submit |
user | http | POST | sudo website |
/my/profile/save |
CustomerPortal.save_edited_profile |
user | jsonrpc | POST | website |
/my/security |
CustomerPortal.security |
user | http | GET, POST | sudo website |
| (inherited route override) | Home.index |
inherited | http | ALL | |
| (inherited route override) | Home.web_client |
inherited | http | ALL | |
/mail/unfollow |
MailController.mail_action_unfollow |
public | http | ALL | website |
Models touched (14)
New fields (0)
No new fields.
Public methods (1)-
get_frontend_session_info(self)@api.model
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (1)
-
customize_showBooleandefault=False args: 'Show As Optional Inherit'
No public methods.
New fields (0)
No new fields.
Public methods (1)-
portal_message_format(self, options=None)Simpler and portal-oriented version of 'message_format'. Purpose is to prepare, organize and format values required by frontend widget (frontend Chatter). This public API asks for read access on messages before doing the actual computation in the private implementation. :param dict options: options, used notably for inheritance and adding specific fields or properties to compute; :returns: list of dict, one per message in self. Each dict contains values for either fields, either properties derived from fields. :rtype: list[dict]
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (9)
-
categoryChardefault='common_category' args: 'Category' -
descriptionTexttranslate=True args: 'Description of Card' -
imageBinaryargs: 'Image' -
is_config_cardBooleandefault=False args: 'Config Card' -
nameCharrequired=Truetranslate=True args: 'Title of Card' -
placeholder_countCharargs: 'Placeholder Count' -
sequenceIntegerdefault='999' args: 'sequence' -
show_in_portalBooleandefault=True args: 'Show in Portal' -
urlCharargs: 'Target URL'
No public methods.
New fields (3)
-
access_tokenCharcopy=Falsesearch='_search_access_token' args: 'Security Token' -
access_urlCharcompute='_compute_access_url'help='Customer Portal URL' args: 'Portal Access URL' -
access_warningTextcompute='_compute_access_warning' args: 'Access warning'
-
action_share(self)@api.model -
get_portal_url(self, suffix=None, report_type=None, download=None, query_string=None, anchor=None, share_token=True)Get a portal url for this model, including access_token if enabled. The associated route must handle the flags for them to have any effect. - suffix: string to append to the url, before the query string - report_type: report_type query string, often one of: html, pdf, text - download: set the download query string to true - query_string: additional query string - anchor: string to append after the anchor # - share_token: boolean to add the access token of the record in portal url
New fields (7)
-
access_warningTextcompute='_compute_access_warning' args: 'Access warning' -
noteTexthelp='Add extra content to display in the email' -
partner_idsMany2many → res.partnerrequired=Truestring='Recipients' args: 'res.partner' -
res_idIntegerrequired=True args: 'Related Document ID' -
res_modelCharrequired=True args: 'Related Document Model' -
resource_refReferencecompute='_compute_resource_ref' args: '_selection_target_model', 'Related Document' -
share_linkCharcompute='_compute_share_link'string='Link'
-
action_send_mail(self) -
default_get(self, fields)@api.model
New fields (3)
-
partner_idsMany2many → res.partnerdefault=_default_partner_idsstring='Partners' args: 'res.partner' -
user_idsOne2many → portal.wizard.usercompute='_compute_user_ids'readonly=Falsestore=Truestring='Users' args: 'portal.wizard.user', 'wizard_id' -
welcome_messageTexthelp='This text is included in the email sent to new users of the portal.' args: 'Invitation Message'
-
action_open_wizard(self)@api.modelCreate a "portal.wizard" and open the form view. We need a server action for that because the one2many "user_ids" records need to exist to be able to execute an a button action on it. If they have no ID, the buttons will be disabled and we won't be able to click on them. That's why we need a server action, to create the records and then open the form view on them.
New fields (8)
-
emailCharargs: 'Email' -
email_stateSelectioncompute='_compute_email_state'default='ok'string='Status' args: [('ok', 'Valid'), ('ko', 'Invalid'), ('exist', 'Already Registered')] -
is_internalBooleancompute='_compute_group_details' args: 'Is Internal' -
is_portalBooleancompute='_compute_group_details' args: 'Is Portal' -
login_dateDatetimerelated='user_id.login_date'string='Latest Authentication' -
partner_idMany2one → res.partnerondelete='cascade'readonly=Truerequired=Truestring='Contact' args: 'res.partner' -
user_idMany2one → res.userscompute='_compute_user_id'compute_sudo=Truestring='User' args: 'res.users' -
wizard_idMany2one → portal.wizardondelete='cascade'required=Truestring='Wizard' args: 'portal.wizard'
-
action_grant_access(self)Grant the portal access to the partner. If the partner has no linked user, we will create a new one in the same company as the partner (or in the current company if not set). An invitation email will be sent to the partner. -
action_invite_again(self)Re-send the invitation email to the partner. -
action_refresh_modal(self)Refresh the portal wizard modal and keep it open. Used as fallback action of email state icon buttons, required as they must be non-disabled buttons to fire mouse events to show tooltips on email state. -
action_revoke_access(self)Archive the portal user of the partner. User is kept in `group_portal` as `group_public` should only be used for automated tasks and guest interactions.
New fields (1)
-
portal_allow_api_keysBooleanconfig_parameter='portal.allow_api_keys'string='Customer API Keys'
No public methods.
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (0)
No new fields.
Public methods (1)-
check_access_make_key(self)
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…